3D adversarial attacks beyond point cloud

被引:13
|
作者
Zhang, Jinlai [1 ]
Chen, Lyujie [2 ]
Liu, Binbin [2 ]
Ouyang, Bo [2 ]
Xie, Qizhi [3 ]
Zhu, Jihong [1 ,3 ]
Li, Weiming [4 ]
Meng, Yanmei [1 ]
机构
[1] Guangxi Univ, Coll Mech Engn, Naning 530004, Guangxi, Peoples R China
[2] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100000, Peoples R China
[3] Tsinghua Univ, Dept Precis Instrument, Beijing 100000, Peoples R China
[4] Samsung Res China Beijing SRC B, Beijing 100000, Beijing, Peoples R China
关键词
Adversarial attack; Point cloud classification; Deep learning; Mesh; ROBUSTNESS;
D O I
10.1016/j.ins.2023.03.084
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, 3D deep learning models have been shown to be susceptible to adversarial attacks like their 2D counterparts. Most of the state-of-the-art (SOTA) 3D adversarial attacks perform perturbation to 3D point clouds. To reproduce these attacks in the physical scenario, a generated adversarial 3D point cloud needs to be reconstructed to mesh, which leads to a significant drop in its adversarial effect. In this paper, we propose a strong 3D adversarial attack named Mesh Attack to address this problem by directly performing perturbation on mesh of a 3D object. In order to take advantage of the most effective gradient-based attack, a differentiable sample module that back-propagate the gradient of point cloud to mesh is introduced. To further ensure the adversarial mesh examples without outlier and 3D printable, three mesh losses are adopted. Extensive experiments demonstrate that the proposed scheme outperforms SOTA 3D attacks by a significant margin. We also achieved SOTA performance under various defenses. Our code will be available at: https://github .com /cuge1995 /Mesh -Attack.
引用
收藏
页码:491 / 503
页数:13
相关论文
共 50 条
  • [1] Adversarial Attacks and Defenses on 3D Point Cloud Classification: A Survey
    Naderi, Hanieh
    Bajic, Ivan V.
    [J]. IEEE ACCESS, 2023, 11 : 144274 - 144295
  • [2] A Survey of Adversarial Attacks on 3D Point Cloud Object Recognition
    Liu, Weiquan
    Zheng, Shijun
    Guo, Yu
    Wang, Cheng
    [J]. Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2024, 46 (05): : 1645 - 1657
  • [3] EXTENDING ADVERSARIAL ATTACKS AND DEFENSES TO DEEP 3D POINT CLOUD CLASSIFIERS
    Liu, Daniel
    Yu, Ronald
    Su, Hao
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2019, : 2279 - 2283
  • [4] Local aggressive and physically realizable adversarial attacks on 3D point cloud
    Chen, Zhiyu
    Chen, Feng
    Sun, Yiming
    Wang, Mingjie
    Liu, Shangdong
    Ji, Yimu
    [J]. COMPUTERS & SECURITY, 2024, 139
  • [5] Compressive imaging for thwarting adversarial attacks on 3D point cloud classifiers
    Kravets, Vladislav
    Javidi, Bahram
    Stern, Adrian
    [J]. OPTICS EXPRESS, 2021, 29 (26): : 42726 - 42737
  • [6] On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks
    Zhao, Yue
    Wu, Yuwei
    Chen, Caihua
    Lim, Andrew
    [J]. 2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 1198 - 1207
  • [7] Adaptive local adversarial attacks on 3D point clouds
    Zheng, Shijun
    Liu, Weiquan
    Shen, Siqi
    Zang, Yu
    Wen, Chenglu
    Cheng, Ming
    Wang, Cheng
    [J]. PATTERN RECOGNITION, 2023, 144
  • [8] Geometric Adversarial Attacks and Defenses on 3D Point Clouds
    Lang, Itai
    Kotlicki, Uriel
    Avidan, Shai
    [J]. 2021 INTERNATIONAL CONFERENCE ON 3D VISION (3DV 2021), 2021, : 1196 - 1205
  • [9] Curvature-Invariant Adversarial Attacks for 3D Point Clouds
    Zhang, Jianping
    Gu, Wenwei
    Huang, Yizhan
    Jiang, Zhihan
    Wu, Weibin
    Lyu, Michael R.
    [J]. THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 7, 2024, : 7142 - 7150
  • [10] PointBA: Towards Backdoor Attacks in 3D Point Cloud
    Li, Xinke
    Chen, Zhirui
    Zhao, Yue
    Tong, Zekun
    Zhao, Yabang
    Lim, Andrew
    Zhou, Joey Tianyi
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16472 - 16481